Bleepingcomputer Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure
Article Content
- •CVE-2026-85706 allows unauthenticated file read access, rated CVSS 10.0.
- •CVE-2026-87719 enables credential theft for authenticated users, rated CVSS 9.9.
- •Active exploitation attempts were reported just one day after the vulnerabilities were disclosed.
On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.7 up to 19.3.2. Just one day after the patches were released, threat intelligence firm WatchTowr reported active exploitation attempts targeting CVE-2026-85706. Organizations running self-managed GitLab instances are urged to upgrade immediately, as the vulnerabilities can expose sensitive data and configurations. The situation is critical, with the potential for widespread exploitation expected soon.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (18)
Following this threat?
Track NoviSpy and CVE-2021-22175 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Serbian Activists Targeted by Advanced Spyware Ahead of Elections Since December 2025, at least 14 individuals in Serbia, including student activists and opposition politicians, have been targeted with advanced spyware, marking the largest documented wave of such surveillance in the country. The attacks coincide with local elections held on March 29, 2026, and are linked to the use…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…